Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

The following analytic detects executable file formats being created within the Confluence main directory.
This can be indicative of exploitation of the Confluence web services to stage malware.
This won't catch adversaries who modify the output location outside the Confluence directory when exploiting.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
Detects DNS-based Kerberos coercion attacks where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication such as in CVE-2025-33073. This detection leverages suricata looking for specific CREDENTIAL_TARGET_INFORMATION structures in DNS queries.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects potential exploitation of the CrushFTP authentication bypass vulnerability (CVE-2025-31161). This detection identifies suspicious command execution patterns associated with exploitation of this vulnerability, such as executing mesch.exe with specific arguments like b64exec or fullinstall. This activity is indicative of an attacker exploiting CVE-2025-31161 to gain unauthorized access to the CrushFTP server and perform post-exploitation activities.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic identifies attempts to inject Log4Shell JNDI payloads via web calls. It leverages the Web datamodel and uses regex to detect patterns like `${jndi:ldap://` in raw web event data, including HTTP headers. This activity is significant because it targets vulnerabilities in Java web applications using Log4j, such as Apache Struts and Solr. If confirmed malicious, this could allow attackers to execute arbitrary code, potentially leading to full system compromise. Immediate investigation is required to determine if the attempt was successful and to mitigate any potential exploitation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
Detects a suspicious sequence of network events consistent with a credential-harvesting campaign abusing the FedCM (Federated Credential Management) API. The rule identifies the initial fetch of a malicious loader script from a lookalike domain (pdf.gusercontent.com), followed closely (within 5 minutes) by a redirect to Google's legitimate 'EmbeddedSetup' sign-in flow containing an email parameter.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Detects a suspicious sequence of network events consistent with a credential-harvesting campaign abusing the FedCM (Federated Credential Management) API. The rule identifies the initial fetch of a malicious loader script from a lookalike domain (pdf.gusercontent.com), followed closely (within 5 minutes) by a redirect to Google's legitimate 'EmbeddedSetup' sign-in flow containing an email parameter.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects a suspicious sequence of network events consistent with a credential-harvesting campaign abusing the FedCM (Federated Credential Management) API. The rule identifies the initial fetch of a malicious loader script from a lookalike domain (pdf.gusercontent.com), followed closely (within 5 minutes) by a redirect to Google's legitimate 'EmbeddedSetup' sign-in flow containing an email parameter.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Page 230 of 1871